Threat Database Trojans Exploit:JS/Dotcaf.A

Exploit:JS/Dotcaf.A

By CagedTech in Trojans

Threat Scorecard

Popularity Rank: 930
Threat Level: 90 % (High)
Infected Computers: 34,004
First Seen: October 22, 2014
Last Seen: November 22, 2025
OS(es) Affected: Windows

Exploit:JS/Dotcaf.A is a threat that may install itself on your computer using known vulnerabilities, freeware programs, e-mail attachments, torrents and may enter the computer bundled with other threats such as HEUR.Trojan.Win32.Generic Virus. Exploit:JS/Dotcaf.A is used by hackers to install Possibly Unwanted Programs or threats on your machine. Exploit:JS/Dotcaf.A opens a backdoor that will be a gateway for third parties to take control of the infected computer. Exploit:JS/Dotcaf.A changes your Web browser settings, adds corrupted codes to your Registry and disables security-related software. Exploit:JS/Dotcaf.A may collect selected data that will be used against the computer user. Exploit:JS/Dotcaf.A is a high-level threat and, as such, should be deleted from the infected computer immediately after been detected to avoid further harm. Computer users should run a deep scan of their systems to detect all the changes made by Exploit:JS/Dotcaf.A, remove it and any related threat.

Analysis Report

General information

Family Name: Trojan.Injector.E
Signature status: No Signature

Known Samples

MD5: 68887a9983368cd741a9ac1ab3c1572d
SHA1: a3a39f02d233c6a0b8e089ce6961fbad4ac081d6
SHA256: 71653A80DD76F94F70B27AA45AE83FB4B80E3865B001BB9AA0063ADA1AE0BEFA
File Size: 3.03 MB, 3029584 bytes
MD5: 73ee59774faf6c435cbd4cc5c0427cc2
SHA1: 90e4cef02053db008f127b60d464ffbf9f42dba2
SHA256: DBDBC4995389014C9237206E1D8F0812B4C8E487BF053DF75CD9234A821AA783
File Size: 1.28 MB, 1282488 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have relocations information
  • File doesn't have security information
  • File has exports table
  • File has TLS information
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
Show More
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Company Name Abyssmedia.com
File Description Audio Converter Plus
File Version 6.9.1.0
Product Name Audio Converter Plus
Product Version 6.9.1.0

Digital Signatures

Signer Root Status
3DP GlobalSign Root Not Trusted

File Traits

  • 2+ executable sections
  • HighEntropy
  • x86

Block Information

Total Blocks: 26
Potentially Malicious Blocks: 2
Whitelisted Blocks: 21
Unknown Blocks: 3

Visual Map

0 0 0 0 x 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? ?
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Files Modified

File Attributes
c:\users\user\appdata\local\temp\nsm62c3.tmp\langdll.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nsx62b3.tmp Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete

Trending

Most Viewed

Loading...